Reporting to the VP, Information Technology, the Cloud & Infrastructure Engineer to partner with our current engineer to bring complementary depth in cloud and on-premises networking, Azure platform engineering, and infrastructure-as-code. This position will be responsible for the reliability, security, and scalability of our Azure environment, Enterprise M365 capabilities, and our on-premises infrastructure The Cloud Engineer is expected to design and operate infrastructure in a manner that protects cardholder data and supports continuous audit readiness.
- Design, deploy, and operate Azure platform services: compute, storage, networking, identity, monitoring, and governance (management groups, subscriptions, policy, RBAC).
- Implement and maintain landing zone patterns, naming and tagging standards, and cost-optimization practices.
- Build and maintain infrastructure-as-code using Terraform and/or Bicep; implement CI/CD for infrastructure changes.
- Operate and tune monitoring, alerting, and logging using Azure Monitor, Log Analytics, and related tooling.
- Own design and operations for cloud and on-premises networking: VNets, subnets, NSGs, route tables, peering, ExpressRoute/VPN, hybrid connectivity, DNS, firewalls, load balancers, and WAN/LAN.
- Implement and maintain network segmentation appropriate for PCI DSS scope; partner with Information Security on network controls.
- Troubleshoot complex hybrid networking issues across cloud, hosted private cloud, and on-prem environments.
- Partner on the design, operations, and lifecycle of our hosted private cloud environment and remaining on-prem infrastructure.
- Maintain backup, disaster recovery, and business continuity capabilities; participate in DR testing.
- Manage server, virtualization, and storage platforms in partnership with the existing Cloud & Infrastructure Engineer.
- Deliver high availability and performance for production and corporate workloads through proactive engineering, capacity planning, and operational excellence.
- Implement and maintain security baselines, hardening standards, and patching; partner closely with the Security Engineer and Information Security Officer.
- Provide engineering evidence and remediation for PCI DSS and SOC 2 Type 2 audits.
- Automate repetitive operational tasks using PowerShell, Python, and CI/CD pipelines (Azure DevOps and/or GitHub Actions).
- Contribute to runbooks, knowledge articles, and self-service capabilities that standardize execution, improving operations and reducing mean time to recovery.
- Supporting specialized projects on an as-needed basis as directed by the VP, Information Technology.
- Support as-hoc tasks and projects as required by departmental and company needs.
- Other duties as assigned.
Qualifications:- 3 - 6 years of hands-on experience in cloud engineering, infrastructure engineering, network engineering, or a closely related role.
- Strong Azure experience across compute, networking, identity, and monitoring; comfortable building and operating production Azure workloads.
- Experience managing and operating within a M365 E5 class environment across the services available in the suite.
- Strong networking fundamentals: TCP/IP, routing, switching, VLANs, DNS, firewalls, VPN, and hybrid connectivity; experience designing and troubleshooting non-trivial network topologies.
- Strong understanding of privileged access governance and hands-on experience implementing it (PAM/PIM/JIT/JEA).
- Hands-on experience with infrastructure-as-code (Terraform and/or Bicep) and source-controlled infrastructure workflows.
- Scripting proficiency in PowerShell and/or Python.
- Practical understanding of security and compliance constructs in a regulated environment (PCI DSS, SOC 2, HIPAA, or similar).
- Strong troubleshooting skills, ownership mindset, and ability to operate calmly under incident conditions.
Preferred:
- Experience in payments, fintech, or another regulated industry.
- Experience with hosted private cloud, colocation, or hybrid product environments.
- Experience with virtualization (VMware, Hyper-V), storage platforms, and enterprise backup/DR tooling.
- Experience with network and security tooling such as Azure Firewall, Palo Alto, Fortinet, SonicWall, Cisco, or comparable.
- Relevant certifications such as Azure Administrator Associate (AZ-104), Azure Network Engineer Associate (AZ-700), Azure Solutions Architect Expert, CCNA/CCNP, or equivalent.
What We Offer:- Competitive Salary, Bonuses and Incentives.
- Comprehensive employer sponsored health, vision, and dental insurance programs.
- Paid time off, Paid Sick and Paid Holidays.
- 401K plan with up to a 3% matching contribution.
- Commitment to Career Development and Advancement.
- Employee Recognition Programs
- Vibrant Office Culture, Team Building, Birthdays, Work Anniversaries, Snacks, and more!
Pay Range: $125K-$140KThis position will report onsite to our offices in Calabasas, CA